Windows AFD WinSock Use-After-Free Privilege Escalation
Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.
- Vendor
- Microsoft
- Product
- Windows (multiple versions)
- CVSS
- 7.0
- EPSS (exploit probability)
- N/A
- Status
- kev
- Published
CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver that backs Windows socket operations. An authorized local attacker can trigger a race condition that corrupts freed memory, leading to SYSTEM privilege escalation.
Microsoft patched this in the August 2026 Patch Tuesday release. BleepingComputer reports that North Korea’s Lazarus group deployed the FudModule rootkit using this vulnerability before the patch was available — making it a confirmed zero-day exploitation in targeted campaigns.
Affected products: Windows (all actively supported versions as of August 2026 Patch Tuesday).
Mitigation: Apply the August 2026 Patch Tuesday cumulative update. No viable workaround exists for this class of kernel driver flaw; patching is the only remediation.
Priority: Immediate — active exploitation confirmed.
